If a cyberattack hits your business, the first hour is the one that matters most.

Before Anything Else: Don't Make It Worse
- Don’t power off the affected computer
If you can help it. Disconnecting it from the network is better — shutting it down can wipe evidence stored in memory that your IT team and investigators will need. - Don’t delete anything.
Leave the ransom note, the suspicious email and any alerts exactly where they are. - Don’t pay a ransom on the spot.
This is a decision that needs to be made calmly, with expert support — not in the first panicked hour. - Don’t use hacked email or accounts to discuss the attack.
If an attacker is in your inbox, they can read those messages. Switch to phone calls or a separate account.
The Step-by-Step Plan
1. Disconnect the Affected Devices from the Network
2. Call Your IT Provider — By Phone
3. Leave the Evidence Alone
4. If Money Was Sent, Call Your Bank Immediately
5. Reset Passwords from a Clean Device and Enable Multi-Factor Authentication
6. Report the Attack
- Australia: Report through ReportCyber or call the 24/7 hotline on 1300 CYBER1.
- United States: File with the FBI’s Internet Crime Complaint Center (IC3) and report to CISA.
- United Kingdom: Report through the NCSC and to Action Fraud.
Where Notification Obligations Come In
- Australia: Notifiable Data Breaches (NDB) scheme under the Privacy Act
- UK and Europe: GDPR
- United States: State breach-notification laws
Expert review note: Notification obligations are a legal matter. Speak with your legal adviser or IT provider early so you don’t miss a reporting deadline.
Should You Pay the Ransom?
The Best Time to Prepare Is Before It Happens
All of this is far easier if you've made some of these decisions in advance. You don't need a thick binder — just a simple one-page plan that covers:
Who to call first — your IT provider and insurer, with numbers you can reach without your main systems.
Where your backups are - and proof they've been tested by restoring from them.
Which accounts and devices matter most - so you know what to protect first.
At iQtec, we help organisations move from reactive security controls to a structured, intelligence-led approach that protects systems, data and people. A plan doesn't need to be complex — it just needs to exist before you need it.
Ready to Build a Response Plan Before You Need One?
If you would like to understand your current cyber risk, discuss framework alignment, or explore whether managed cyber security is right for your organisation, Get in touch and speak with the iQtec team today.
